Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,244 rules
Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-03-11Windows process access indicating potential shellcode injection to lsass.exe
Alerts on high-privilege process access from wmiprvse.exe to lsass.exe consistent with potential shellcode injection behavior.
Bhabesh Raj, Huntrule TeamWindowsprocess_accessMedium90Free2022-03-11Windows: Executable Creates Executable via File Creation Events
Flags .exe-to-.exe executable drops on Windows when a running executable creates another .exe, with exclusions for common system/update paths.
frack113, Huntrule TeamWindowsfile_eventLow70Free2022-03-09Windows Process Creation: OfflineScannerShell.exe mpclient.dll DLL Sideloading Risk
Detects OfflineScannerShell.exe launched with an unexpected current directory that could enable mpclient.dll sideloading.
frack113, Huntrule TeamWindowsprocess_creationMedium393Free2022-03-06Windows Process Creation: Replace.exe with -a argument
Detects Replace.exe executions that include the -a argument, which may be used for file replacement.
frack113, Huntrule TeamWindowsprocess_creationMedium265Free2022-03-06Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh151Free2022-03-04PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh147Free2022-03-04Windows Hacktool Execution Flagged by Imphash in Process Creation
Alerts on Windows process executions where the import hash matches known hacktool binaries, even if renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical486Free2022-03-04Windows PowerShell: Disable Microsoft Defender Scanning via Set-MpPreference
Flags PowerShell commands that disable Microsoft Defender scanning/protection settings using Set-MpPreference, including encoded variants.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh308Free2022-03-03Windows: fsutil SymlinkEvaluation behavior modification via command line
Alerts on fsutil commands from cmd/PowerShell that change NTFS SymlinkEvaluation behavior, potentially enabling remote symlink access.
frack113, The DFIR Report, Huntrule TeamWindowsprocess_creationMedium327Free2022-03-02Windows Process Creation: Base64-Obfuscated .NET Reflection Assembly Load Call
Alerts on command lines containing Base64-encoded obfuscation for .NET reflection assembly load calls.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2022-03-01Windows PowerShell: Base64 Encoded Reflective .NET Assembly Load
Flags PowerShell command lines containing Base64 fragments consistent with reflective .NET Assembly.Load usage.
Christian Burkard (Nextron Systems), pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh194Free2022-03-01Windows BITS Transfer Jobs Downloading Files with Suspicious Extensions
Flags Windows BITS transfers saving local files with high-risk script/executable extensions while excluding common benign patterns.
frack113, Huntrule TeamWindowsbits-clientMedium152Free2022-03-01Windows BITS Job Creation Triggered by PowerShell
Flags new BITS job creation on Windows when initiated by PowerShell (Event ID 3).
frack113, Huntrule TeamWindowsbits-clientLow111Free2022-03-01